CVE-2018-1273CISA KEVEPSS p99.9%

CVE-2018-1273CVE-2018-1273

broadcom / spring_data_commons

Description

Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (or attacker) can supply specially crafted request parameters against Spring Data REST backed HTTP resources or using Spring Data's projection-based request payload binding hat can lead to a remote code execution attack.

Scoring

CVSS 9.8 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS95.65% probability of exploitation · percentile 99.9% · 2026-06-15T12:03:41Z
Last modified2026-06-15

CISA KEV entry

Added to KEV: 2022-03-25

(incoming)1

TypeTargetConfidenceTier
KEVEntryVMware Tanzu Spring Data Commons Property Binder Vulnerabilitykev-cve-2018-12730%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability
CVE
Spring Framework JDK 9+ Remote Code Execution Vulnerability
CVE
VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability
CVE
VMware Spring Cloud Gateway Code Injection Vulnerability
CVE
CVE-2026-41695
CVE
XStream Remote Code Execution Vulnerability
Sourced from NVD + CISA KEV + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.